Description
WordPress Plugin All in One SEO-Best WordPress SEO-Easily Improve SEO Rankings & Increase Traffic is prone to multiple vulnerabilities, including SQL injection and privilege escalation vulnerabilities. Exploiting these issues may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database, or to perform otherwise restricted actions and subsequently access protected REST API endpoints. WordPress Plugin All in One SEO-Best WordPress SEO-Easily Improve SEO Rankings & Increase Traffic versions between 4.0.0 - 4.1.5.2 and 4.1.3.1 - 4.1.5.2 (inclusively) are vulnerable.
Remediation
Update to plugin version 4.1.5.3 or latest
References
Related Vulnerabilities
LiteSpeed Web Server Out-of-bounds Read Vulnerability (CVE-2004-0112)
MySQL CVE-2014-0412 Vulnerability (CVE-2014-0412)
Oracle Database Server Other Vulnerability (CVE-2005-3206)
WordPress Plugin Startklar Elementor Addons Directory Traversal (1.7.15)
WordPress Plugin WP-Syntax Remote PHP Code Execution (0.9.9)